DSA-4817-1 php-pear -- security update

Related Vulnerabilities: CVE-2020-28948   CVE-2020-28949  

Two vulnerabilities were discovered in the PEAR Archive_Tar package for handling tar files in PHP, potentially allowing a remote attacker to execute arbitrary code or overwrite files. For the stable distribution (buster), these problems have been fixed in version 1:1.10.6+submodules+notgz-1.1+deb10u1. We recommend that you upgrade your php-pear packages. For the detailed security status of php-pear please refer to its security tracker page at: https://security-tracker.debian.org/tracker/php-pear

Debian Security Advisory

DSA-4817-1 php-pear -- security update

Date Reported:
19 Dec 2020
Affected Packages:
php-pear
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 976108.
In Mitre's CVE dictionary: CVE-2020-28948, CVE-2020-28949.
More information:

Two vulnerabilities were discovered in the PEAR Archive_Tar package for handling tar files in PHP, potentially allowing a remote attacker to execute arbitrary code or overwrite files.

For the stable distribution (buster), these problems have been fixed in version 1:1.10.6+submodules+notgz-1.1+deb10u1.

We recommend that you upgrade your php-pear packages.

For the detailed security status of php-pear please refer to its security tracker page at: https://security-tracker.debian.org/tracker/php-pear